ChatGPT Security History: Review Sign-Ins and Changes
ChatGPT security history gives OpenAI account holders a dated record of sign-ins, sign-outs and authentication-setting changes on the web.
ChatGPT security history is a new web setting for reviewing recent security activity on an OpenAI account. OpenAI introduced it on September 25, 2026. The log can show sign-ins, sign-outs, password changes, and changes to multi-factor authentication, passkeys and other security settings. Each event can include a time, location and device, although OpenAI says some details may be approximate or unavailable. To open it, use ChatGPT on the web and go to Settings → Security and login → Security history. OpenAI announced the feature in the ChatGPT release notes.
ChatGPT security history: what it records
The new page answers a practical account-security question: what recently happened to the account? OpenAI lists several event types—sign-ins, sign-outs, password changes, MFA changes, passkey changes and other security-setting changes. A person reviewing the log can compare the event type and time with the displayed location and device details.
That is more useful than a generic statement that an account is secure because it exposes a sequence of events to inspect. A sign-in from an expected device may explain a routine entry. A passkey or MFA change that the account owner did not make is a stronger reason to start the recovery steps in OpenAI’s security guide.
The location and device columns are evidence, not perfect identification. OpenAI explicitly warns that some details may be approximate or unavailable. A city label can therefore help with review, but it should not be treated as proof of who performed an action. The event type, time and the account owner’s own activity should be considered together.
This update is separate from the ChatGPT Privacy Center. Privacy Center brings together explanations and links for privacy, memory, personalization, data use, connected apps and account security. Security history is the dated activity log inside Security and login. One is a navigation and education hub; the other is a record to examine when checking account access.
How to review ChatGPT security history
OpenAI documents a three-step path on the web:
- Open Settings in ChatGPT.
- Select Security and login.
- Select Security history.
Review each event’s type and timestamp first, then compare the location and device details with devices and sessions you recognize. A useful review starts with the newest entries and works backward through the period shown in the account. Look for actions that matter more than a routine sign-in, such as a password, MFA or passkey change that you did not initiate.
The official materials call the feature “recent” security history but do not publish a retention period or promise that every historical event is available. They also do not describe an export button, automated alerts for each entry, a mobile navigation path or plan-by-plan availability. Those details should not be inferred from the web instructions.
If an entry is unfamiliar, preserve the visible information before taking recovery steps. OpenAI specifically recommends keeping details that may help with account recovery. That can include the event type, time, approximate location and device description shown in the history. Do not post those details publicly, because they are part of an account-security investigation.
Security history versus Active sessions
Security history and Active sessions answer different questions. OpenAI describes Security history as a record of past security events. Active sessions shows current sessions and provides controls to manage them. A historical sign-out can appear in the former even though there is no current session to revoke; a currently active session belongs in the latter.
For current access, go to Settings → Security and login → Active sessions. OpenAI provides a Log out of all sessions action there. Confirming it signs the account out across devices, including the current session. The guide says other ChatGPT sessions may take up to 30 minutes to be logged out.
This distinction matters during incident response. Reading the log helps establish what changed and when. Ending active sessions removes existing access. Enabling MFA alone does not cancel existing logins, according to OpenAI, so a person who suspects unauthorized access should not treat a new second factor as a substitute for changing an exposed password and logging out sessions.
For people who use multiple connected services, the existing report on multiple ChatGPT plugin accounts is relevant to reviewing which personal and work accounts are connected. It does not replace the OpenAI account’s own Security history or Active sessions controls.
What to do when an event is unfamiliar
OpenAI’s account-security guide gives a specific response sequence. If a password may have been exposed, reused or shared, change it immediately. Log out of all sessions. If the account also uses the OpenAI API, delete existing API keys and inspect API usage for unexpected activity. Review Security history, keep relevant event details and contact OpenAI Support through a Help Center chat.
API keys require a separate check because a suspicious account event and unauthorized API use are related but not identical problems. Deleting an exposed key stops that credential from being reused; reviewing usage can reveal activity that needs to be documented. The site’s OpenAI API overview explains the API surface, while the official security guide remains the source for key-protection and compromise-response steps.
For prevention, OpenAI recommends a strong, unique password stored with a password manager and enabling MFA. It also advises storing API keys in environment variables or a secrets system rather than application code, avoiding keys in mobile apps, reviewing code before publishing, using separate keys for different projects and monitoring usage and spend.
The security guide says OpenAI disables a key when it detects the key on the public internet or leaked inside an app-store application. That protection should not be used as a reason to wait: the documented response to a suspected key compromise is to delete the affected key, inspect usage and contact support.
What changed for account owners
Before this release, ChatGPT settings already included security controls and session management. The September 25 update adds a user-facing record of recent account-security events and puts it next to the controls used to manage access. The practical improvement is visibility: users can now inspect when relevant account actions occurred instead of relying only on current settings.
The feature does not certify that every displayed event is malicious or that an unlisted event never happened. It provides review data with known limits on location and device precision. Its strongest use is as part of a response workflow: compare recent events with your own activity, preserve unfamiliar details, end active sessions, rotate exposed credentials and contact support when needed.
OpenAI’s two official pages establish the feature, the web path and the recovery steps. They do not announce a GPT-6 model change, pricing change or API feature. This is an account-control update for ChatGPT users, and the correct first action is simply to open Security history and verify that the recent events match activity you recognize.